User plane function device and methods

The method of using a UPF device to inspect and block anomalous traffic packets in communication networks effectively addresses the challenge of DDoS attacks by releasing user data tunnels and reducing network resource overload.

WO2025127978A1PCT designated stage expired Publication Date: 2025-06-19TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/SE2024/050141
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-12
Filing Date
2024-02-14
Publication Date
2025-06-19

AI Technical Summary

Technical Problem

Current communication networks face challenges in effectively mitigating distributed denial-of-service (DDoS) attacks, which overwhelm resources by flooding the network with anomalous traffic packets, leading to performance degradation and security breaches.

Method used

A method is introduced where a user plane function (UPF) device in the communication network inspects incoming traffic packets, determines if they are anomalous, and sends a message to the radio access network (RAN) device to release user data tunnels associated with the communication device, thereby blocking further anomalous traffic.

Benefits of technology

This approach enhances network security by promptly identifying and blocking anomalous traffic, reducing the load on network resources and preventing the overload scenarios typically caused by DDoS attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure SE2024050141_19062025_PF_FP_ABST
    Figure SE2024050141_19062025_PF_FP_ABST
Patent Text Reader

Abstract

A method performed in a user plane function, UPF, device (120) in a communication network (100) The method comprises receiving (210) traffic packets from a communication device (105) via a radio access network, RAN, device (110) of the communication network (100). The method further comprises determining (220) if the traffic packets received from the communication device are comprising at least one anomalous traffic packet. The method comprises in response to an anomaly determination that at least one anomalous traffic packet has been received. The method comprises, sending (230) a first message to the RAN device, wherein the first message comprises a first indication for a release of a user data tunnel associated with the communication device. Further there is a radio access network, RAN, device (110) related method, access and mobility management function, AMF, device (140) related method and unified data management (UDM) device, (170) related method, related UPF device, RAN device, AMF device, UDM device.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] USER PLANE FUNCTION DEVICE AND METHODS

[0002] TECHNICAL FIELD

[0003] The disclosure relates to a user plane function (UPF) device, an access and mobility management function (AMF) device, a radio access network (RAN) device and a unified data management (UDM) device and methods performed by the UPF device, AMF device, RAN device, and UDM device. A related computer program, and computer readable storage mediums are also disclosed.

[0004] BACKGROUND

[0005] Denial of service attacks (DoS) attacks may be cyber-attacks which make a machine or a network resource unavailable to a user by temporarily disrupting services if a host of the machine or network resource is connected to a network, such as a communication network. Typically, the DoS attack is accomplished by flooding a target, such as the communication network or resource(s) with superfluous requests in an attempt to overload the target and prevent requests from being fulfilled.

[0006] In a distributed denial-of-service attack (DDoS attack), the incoming traffic flooding the target originates from many different sources. More sophisticated strategies are required to mitigate this type of attack as simply attempting to block a single source is insufficient as there are multiple sources.

[0007] Attacks based on fraudulent traffic relate to for example, traffic associated with subscribers which aim to be charged less than their corresponding tariffs agreed with an operator.

[0008] The communication network may include a Unified Packet Function (UPF) device configured to inspect incoming traffic packets from a communication device. In an attack situation, it is not possible to determine if the traffic packets are anomalous until the incoming traffic packets are inspected by the UPF device. The inspection is done by analyzing, for example, the number of flows created per second against a configured threshold. Once the UPF device has detected that the packets are anomalous, the UPF device may decide to block / drop all of the anomalous packets based on corresponding policies. The policies are previous configured in the UPF device or configured in a control plane, e.g., a policy control function (PCF) device and provided via the SMF device. Blocking and / or dropping avoids forwarding the anomalous packets to their destination. The communication network resources, such as radio access network node (RAN) device resources or e.g., devices hosting network functions (NFs), such as an access management function (AMF) device and / or a session management function (SMF) device , may already be occupied with processing the incoming anomalous traffic packets. Deleting all context information that is being stored on NF nodes and RAN nodes such as a gNb in 5G ends in an overload of the devices hosting the NFs such as the AMF device or SMF device in the communication network, fulfilling the intention of the attack.

[0009] The UPF device stores a context information as part of a session associated to the communication device including for each individual flow: a 5-tuple and other information such as, a packet detection rule (PDR) associated to the packet flow, the accumulated volume for each packet flow, etc. Thus, deleting the context information has a cost in memory and in a Central Processing Unit (CPU) by processing each packet flow comprising a at least one traffic packets individually. As inspection policies are applied to the UPF device for each anomalous traffic packet detected, the attack may result in a continuous detection block task, resulting in a continuous high load. The attack may further impact the performance based in the CPU and memory needed in case of e.g. a DDoS attack. The UPF device might get overloaded by processing such amount of user plane data and applying the corresponding policies.

[0010] 3rd Generation Partnership Project (3GPP) Technical Specification (TS) 23.501 V18.3.0 “System architecture for the 5G System (5GS)” refers to an SMF controlling the functionality of the UPF using N4 session management procedures comprising PDRs that contain information to classify traffic for a protocol data unit (PDU) session. SUMMARY

[0011] An object of the invention is to enable higher security in a communication network.

[0012] A first aspect of the invention relates to a method performed by a user plane function, UPF, device in a communication network. The method comprises receiving traffic packets from a communication device via a radio access network, RAN, device of the communication network, determining if the traffic packets received from the communication device are comprising at least one anomalous traffic packet, and in response to an anomaly determination that at least one anomalous traffic packet has been received, sending a first message to the RAN device, wherein the first message comprises a first indication for a release of a user data tunnel associated with the communication device. Thereby, in response to the anomaly determination, the indication is propagated to release the communication device.

[0013] According to an embodiment of the first aspect, the first message is configured to trigger the RAN device to, block traffic packets from the communication device, and / or release user data tunnels associated with the communication device, and / or send a second message to an access and mobility management function, AMF, device in the communication network, wherein the second message comprises the first indication. Thereby, the RAN device is triggered to release the user data tunnel associated with the communication device or block the traffic packet from the communication device and propagate the indication.

[0014] According to an embodiment of the first aspect, a second message is configured to trigger the AMF device to send a request for deregistration of the AMF device to a unified data management, UDM, device in the communication network, wherein the request comprises the first indication. Thereby, the AMF device is deregistered, and the first indication is propagated.

[0015] According to an embodiment of the first aspect, a request is configured to trigger a unified data management, UDM, device in the communication network to deny access of the communication device to the communication network. Thereby, the communication device is not able to access the communication network.

[0016] According to an embodiment of the first aspect, the first message and / or a second message and / or a request comprises a second indication of an anomaly determination. Thereby, the second indication is propagated.

[0017] According to an embodiment of the first aspect, the at least one anomalous traffic packet comprises at least one fraudulent traffic packet and / or a set of traffic packets related to a Denial-of-service, DoS, attack.

[0018] According to an embodiment of the first aspect, the method further comprises receiving an association setup request from a session management function, SMF, device in the communication network and sending a response related to the association setup request to the SMF device, wherein the response comprises a report of at least one user plane function, UPF, device capability. Thereby, the UPF device reports the capability of for example determination of anomalous traffic packets.

[0019] According to an embodiment of the first aspect, the UPF device capability comprises a feature, wherein the feature comprises at least one of a user data tunnel release feature and an anomaly determination feature.

[0020] According to an embodiment of the first aspect, the method further comprising receiving a session establishment request from a session management function, SMF, device in the communication network, wherein the session establishment request comprises at least one of an anomaly determination policy and a user data tunnel release policy, and sending a response related to the session establishment request to the SMF. Thereby, a session associated to the communication device is enabled to be established.

[0021] According to an embodiment of the first aspect, the method further comprises receiving a deletion notification from a session management function, SMF, device in the communication network. Hereby it is achieved that the session associated to the communication device is enabled to be deleted.

[0022] According to an embodiment of the first aspect, the method further comprises forwarding traffic packets between the RAN device and a network. Thereby, traffic packets flow from the communication device to the core network.

[0023] A second aspect of the invention relates to a method performed by a radio access network, RAN, device of a communication network. The method comprises, receiving a first message from a user plane function, UPF, device in the communication network, wherein the first message comprises a first indication for a release of a user data tunnel associated with a communication device, and in response to receiving the message: blocking traffic packets from the communication device, and / or releasing user data tunnels associated with the communication device. Thereby, the RAN device is triggered to release the user data tunnel associated with the communication device or block the traffic packet from the communication device. According to an embodiment of the second aspect, the method further comprises sending a second message to an access and mobility management function, AMF, device in the communication network, wherein the second message comprises the first indication. Thereby, the first indication is propagated.

[0024] According to an embodiment of the second aspect, a second message is configured to trigger an access and mobility management function, AMF, device in the communication network to send a request for deregistration of the AMF device to a unified data management, UDM, device, in the communication network, wherein the request comprises the first indication. Thereby, the AMF device is deregistered, and the first indication is propagated.

[0025] According to an embodiment of the second aspect, the request is configured to trigger the UDM device to deny access of the communication device to the communication network. Thereby, the communication device is not able to access the communication network.

[0026] According to an embodiment of the second aspect, the first message and / or a second message and / or a request comprises a second indication of an anomaly determination. Thereby, the second indication is propagated.

[0027] According to an embodiment of the second aspect, blocking traffic packets associated with the communication device comprises denying uplink slots for uplink transmission of traffic packets from the communication device. Thereby, the communication device is not able to use uplink slots for uplink transmission of traffic packets.

[0028] According to an embodiment of the second aspect, the method further comprises forwarding traffic packets between the communication device and the UPF. Thereby, traffic packets flow from the communication device to the core network.

[0029] According to an embodiment of the second aspect, the method further comprises receiving a third message, from an access and mobility management function, AMF, device in the communication network, forwarding the third message to the communication device, and wherein the third message indicates that all resources of a session associated with the communication device are to be released by the RAN. Thereby, the communication device is not able to contact the RAN device after receiving the third message.

[0030] A third aspect of the invention relates to a method performed by an access and mobility management function, AMF, device in a communication network, the method comprises receiving a second message from a radio access network node, RAN, device in the communication network, wherein the second message comprises a first indication for a release of a user data tunnel associated with a communication device, and in response to receiving the second message, sending, to a unified data management, UDM, device in the communication network, a request for deregistration of the AMF device, wherein the request comprises the first indication for the release of the user data tunnel associated with the communication device. Thereby, the AMF device gets deregistered, and the first indication is propagated.

[0031] According to an embodiment of the third aspect, the second message and / or the request comprises a second indication of an anomaly determination. Thereby, the second indication is propagated.

[0032] According to an embodiment of the third aspect, the method further comprises receiving, from the UDM device, a response related to the request for deregistration of the AMF. Thereby, the AMF device gets notified.

[0033] According to an embodiment of the third aspect, the request is configured to trigger the UDM device to deny access of the communication device to the communication network. Thereby, the communication device is not able to access the communication network.

[0034] According to an embodiment of the third aspect, the method further comprises sending via the RAN device to the communication device a third message indicating to release all resources of a session associated with the communication device. Thereby, the RAN device is indicated to release all resources of the session associated with the communication device.

[0035] According to an embodiment of the third aspect, the third message is configured to prevent the communication device to send traffic packets to the communication network. According to an embodiment of the third aspect, the method further comprises in response to receiving the second message sending an unsubscribe request associated with a set of subscription data to the UDM device and receiving an unsubscribe response associated with the set of subscription data from the UDM device. Thereby, the AMF device is unsubscribed from the set of subscription data,

[0036] According to an embodiment of the third aspect, the method comprises receiving a session establishment request from the communication device via the RAN, device in response to receiving the session establishment request, selecting a session management function, SMF, device and sending a session create message to the SMF. Thereby, a session associated to the communication device is created.

[0037] In an embodiment, the session create message is configured to trigger the SMF device to select a policy control function, PCF, device in the communication network, send a first request message to retrieve policies for the session associated to the communication device to the PCF device, receive a first response related to the first request message from the PCF device, wherein the response comprises at least one of an anomaly determination policy and a user data tunnel release policy, and select a user plane function, UPF, device supporting the at least one of the anomaly determination policy and the user data tunnel release policy. Thereby, a UPF device is selected supporting the anomaly determination policy and the user data tunnel release policy.

[0038] In an embodiment, the request triggers the PCF device to send a second request message to retrieve the policies for the session associated to the communication device to a unified data repository, UDR, device and receive a second response message comprising the policies for the session associated to the communication device from the UDR device, wherein the response comprises at least one of an anomaly determination policy and a user data tunnel release policy. Thereby, the policies for the session associated to the communication are retrieved.

[0039] A fourth aspect of the invention relates to a method performed by a unified data management, UDM, device in a communication network. The method comprises receiving, from an access and mobility management function, AMF, device in the communication network, a request for deregistration of the AMF device, wherein the request comprises a first indication for a release of a user data tunnel associated with a communication device, and in response to receiving the request for deregistration of the AMF device, denying access of the communication device to the communication network. Thereby, the communication device is not able to access the communication network.

[0040] According to an embodiment of the fourth aspect, wherein the request comprises a second indication of an anomaly determination. Thereby, the second indication is propagated.

[0041] According to an embodiment of the fourth aspect, denying the communication device access to the communication network comprises sending an update message to a unified data repository, UDR, device in the communication network. Thereby, the UDR device is updated.

[0042] In an embodiment, denying the communication device access to the communication network comprises receiving a response to the update message from the UDR device in the communication network.

[0043] In an embodiment, the update message is configured to trigger the UDR device to modify subscription data associated with the communication device. Thereby, the UDR device is triggered to modify subscription data.

[0044] In an embodiment, modifying the subscription data associated to the communication device comprises changing the subscription data associated to the communication device to denied. Thereby, the UDR device is triggered to modify subscription data to deny further creation of sessions associated with the communication device.

[0045] According to an embodiment of the fourth aspect, the method further comprises setting a communication device purged flag associated with an access type, and sending to the AMF device a response related to the request of deregistration of the AMF. Thereby, a purged flag is set.

[0046] According to an embodiment of the fourth aspect, the method further comprising receiving an unsubscribe request associated with a set of subscription data from the AMF device, in response to receiving the unsubscribe request of the AMF device, unsubscribing the AMF device from at least a part of the set of subscription data, and sending, to the AMF device, an unsubscribe response associated with the set of subscription data. Thereby, the AMF device is unsubscribed from the set of subscription data,

[0047] According to an embodiment of the fourth aspect, the method comprising sending, to a unified data repository, UDR, device in the communication network, an unsubscribe request associated with a set of subscription data, and receiving, from the UDR device, an unsubscribe response associated with the set of subscription data. Thereby, the UDM is unsubscribed from the set of subscription data.

[0048] According to an embodiment of the fourth aspect, the method further comprises sending a session release request to a session management function, SMF, device and receiving a session release response from the SMF. Thereby, the SMF device is triggered to release the session associated with the communication device.

[0049] A fifth aspect of the invention relates to a user plane function, UPF, device in a communication network, configured to receive traffic packets from a communication device via a radio access network, RAN, device of the communication network, determine if the traffic packets received from the communication device are comprising at least one anomalous traffic packet, and in response to an anomaly determination that at least one anomalous traffic packet has been received, send a first message to the RAN, device wherein the first message comprises a first indication for a release of a user data tunnel associated with the communication device.

[0050] According to an embodiment of the fifth aspect, the UPF device may be configured to perform the method according to the first aspect or any embodiment of the first aspect.

[0051] A sixth aspect of the invention relates to a user plane function, UPF, device in a communication network, comprising a processor and a memory, the memory containing instructions executable by the processor whereby the UPF device is configured to receive traffic packets from a communication device via a radio access network, RAN, device of the communication network, determine if the traffic packets received from the communication device are comprising at least one anomalous traffic packet, and in response to an anomaly determination that at least one anomalous traffic packet has been received, send a first message to the RAN device, wherein the first message comprises a first indication for a release of a user data tunnel associated with the communication device.

[0052] According to an embodiment of the sixth aspect, the UPF device may be configured to perform the method according to the first aspect or any embodiment of the first aspect.

[0053] A seventh aspect of the invention relates to a radio access network, RAN, device in a communication network, configured to receive a first message from a user plane function, UPF, device in the communication network, wherein the message comprises a first indication for a release of a user data tunnel associated with a communication device, in response to receiving the message: block traffic packets from the communication device, and / or release user data tunnels associated with the communication device and the RAN.

[0054] According to an embodiment of the seventh aspect, the RAN device may be configured to perform the method according to the second aspect or any embodiment of the second aspect.

[0055] A eighth aspect of the invention relates a radio access network, RAN, device in a communication network, comprising a processor and a memory, the memory containing instructions executable by the processor whereby the RAN device is configured to receive a first message from a user plane function, UPF, device in the communication network, wherein the message comprises a first indication for a release of a user data tunnel associated with a communication device, in response to receiving the message: block traffic packets from the communication device, and / or release user data tunnels associated with the communication device and the RAN.

[0056] According to an embodiment of the eighth aspect, the RAN device may be configured to perform the method according to the second aspect or any embodiment of the second aspect.

[0057] A ninth aspect of the invention relates an access and mobility management function, AMF, device in a communication network, configured to receive a second message from a radio access network, RAN, device in the communication network, wherein the message comprises a first indication for a release of a user data tunnel associated with a communication device, in response to receiving the second message, send, to a unified data management, UDM, device in the communication network, a request for deregistration of the AMF device, wherein the request comprises the first indication for the release of the user data tunnel associated with the communication device.

[0058] According to an embodiment of the ninth aspect, the AMF device may be configured to perform the method according to the third aspect or any embodiment of the third aspect.

[0059] A tenth aspect of the invention relates to an access and mobility management function, AMF, device in a communication network, comprising a processor and a memory, the memory containing instructions executable by the processor whereby the AMF device is configured to receive a second message from a radio access network, RAN, device in the communication network, wherein the message comprises a first indication for a release of a user data tunnel associated with a communication device, in response to receiving the second message, send, to a unified data management, UDM, device in the communication network, a request for deregistration of the AMF device, wherein the request comprises the first indication for the release of the user data tunnel associated with the communication device.

[0060] According to an embodiment of the tenth aspect, the AMF device may be configured to perform the method according to the third aspect or any embodiment of the third aspect.

[0061] An eleventh aspect of the invention relates to a unified data management, UDM, device in a communication network, configured to receive, from an access and mobility management function, AMF, device in the communication network, a request for deregistration of the AMF device, wherein the request comprises a first indication for a release of a user data tunnel associated with a communication device, and in response to receiving the request for deregistration of the AMF, device deny access of the communication device to the communication network.

[0062] According to an embodiment of the eleventh aspect, the AMF device may be configured to perform the method according to the fourth aspect or any embodiment of the fourth aspect. A twelfth aspect of the invention relates to a unified data management, UDM, device, in a communication network, comprising a processor and a memory, the memory containing instructions executable by the processor whereby the UDM device is configured to receive, from an access and mobility management function, AMF, device in the communication network, a request for deregistration of the AMF device, wherein the request comprises a first indication for a release of a user data tunnel associated with a communication device, and in response to receiving the request for deregistration of the AMF device, deny access of the communication device to the communication network.

[0063] According to an embodiment of the twelfth aspect, the UDM device may be configured to perform the method according to the fourth aspect or any embodiment of the fourth aspect.

[0064] A thirteenth aspect of the invention relates to a computer program product stored on a non-transitory computer readable medium and comprising instructions that, when executed on at least one processor of a user plane function, UPF, device cause the at least one processor of the UPF device to carry out the method according to the first aspect or any embodiment of the first aspect, and / or at least one processor of a radio access network, RAN, device cause the at least one processor of the RAN device to carry out the method according to the second aspect or any embodiment of the second aspect, and / or at least one processor of an access and mobility management function, AMF, device cause the at least one processor of the AMF device to carry out the method according to the third aspect or any embodiment of the third aspect, and / or at least one processor of a unified data management, UDM, device cause the at least one processor of the UDM device to carry out the method according to the fourth aspect or any embodiment of the fourth aspect.

[0065] A fourteenth aspect of the invention relates to a computer program comprising instructions which, when executed on at least one processor of a user plane function, UPF, device cause the at least one processor of the UPF device to carry out the method according to method according to the first aspect or any embodiment of the first aspect, and / or at least one processor of a radio access network, RAN, device cause the at least one processor of the RAN device to carry out the method according to method according to the second aspect or any embodiment of the second aspect, and / or at least one processor of an access and mobility management function, AMF, device cause the at least one processor of the AMF device to carry out the method according method according to the third aspect or any embodiment of the third aspect, and / or at least one processor of a unified data management, UDM, device cause the at least one processor of the UDM device to carry out the method according to method according to the fourth aspect or any embodiment of the fourth aspect.

[0066] A fifteenth aspect of the invention relates to a tangible, non-transitory-computer- readable medium comprising instructions that, when executed on at least one processor of a user plane function, UPF, device cause the at least one processor of the UPF device to perform the method according to the first aspect or any embodiment of the first aspect, at least one processor of a radio access network, RAN, device cause the at least one processor of the RAN device to perform the method according to the second aspect or any embodiment of the second aspect, and / or at least one processor of an access and mobility management function, AMF, device cause the at least one processor of the AMF device to perform the method according to the third aspect or any embodiment of the third aspect, and / or at least one processor of a unified data management, UDM, device cause the at least one processor of the UDM device to perform the method according to the fourth aspect or any embodiment of the fourth aspect.

[0067] BRIEF DESCRIPTION OF THE DRAWINGS

[0068] Figure 1 shows a schematic diagram illustrating an example of an environment in which embodiments presented herein can be applied

[0069] Figure 2 is a flowchart illustrating a method performed by the UPF device in the communication network

[0070] Figure 3 is a flowchart illustrating a method performed by the RAN device of the communication network

[0071] Figure 4 is a flowchart illustrating a method performed by the AMF device in the communication network

[0072] Figure 5 is a flowchart illustrating a method performed by the UDM device in the communication network Figures 6A to 6D are signaling diagrams of an exemplary interaction between the communication device, the RAN device, the AMF device', the SMF device, the PCF device, the UPF device the UDM device, the UDR device and the network

[0073] Figure 7 is a flowchart illustrating embodiments of the method performed by the UPF device

[0074] Figure 8 is a flowchart illustrating embodiments of the method performed by the RAN device of the communication network

[0075] Figure 9 is a flowchart illustrating embodiments of the method performed by the AMF device of the communication network

[0076] Figure 10 is a flowchart illustrating embodiments of the method performed by the UDM device of the communication network

[0077] Figure 11 shows an example of a communication system in accordance with some embodiments

[0078] Figure 13 illustrates a block diagram illustrating embodiments of the RAN device

[0079] Figure 14 illustrates a block diagram illustrating embodiments of the AMF device

[0080] Figure 15 illustrates a block diagram illustrating embodiments of the UDM device

[0081] DETAILED DESCRIPTION

[0082] Figure 1 illustrates a schematic diagram illustrating an example of an environment in which embodiments presented herein can be applied. Figure 1 illustrates a communication network 100, comprising a core network 190 and an access network node, such as a radio access network (RAN) device node 110. A communication device 105 communicates via the RAN device with the core network. The core network may comprise devices hosting network functions (NFs), such as a user plane function (UPF) device120, an access management function (AMF) device 140, a session management function (SMF) device 150, a user plane function (UPF) device120, a policy control function (PCF) device 180, a unified data management (UDM) device 170, a unified data repository (UDR) device 160 and a network 130. The network may refer to a data network. In an example the UDM device is hosting the UDM function. The AMF device may be configured interact with the access network node and the communication device through, e.g., signaling over N2 and N1 interfaces respectively. Connections towards all other NFs are managed, e.g., via service-based interfaces. The AMF device is involved in, e.g., most of the signaling call flows in a communication network. The AMF device may host an AMF. The SMF device supports different functionalities, e.g., receiving policy and charging control (PCC) rules from the PCF device and configures the UPF device accordingly. The SMF device may host a SMF. The PCF device may host a PCF. The UPF device may support handling of traffic packet flow based on the rules received from the SMF device, e.g., packet inspection and different enforcement actions such as QoS handling. In an example the UPF device hosts an UPF. The UPF device may be a UPF host hosting the functional network element of the user plane. The RAN device is the part of the communication network that enables connection between communication devices 105 and the core network 190. The RAN device is for example a RAN node. Further, the RAN device may be a radio base station, such as a gNodeB (gNB) or a eNodeB (eNB). Traffic packets are sent from the communication device 105 to the communication network, for example, using user plane tunnel protocols, such as e.g., GTP-U (General packet radio service (GPRS) tunneling protocol user plane) in a communication network such as a 4G, 5G or 6G communication network defined by 3rd Generation Partnership Project (3GPP). In this example, GTP-U is a tunneling protocol that exists between a network node in the access network node and 5G user plane.

[0083] Figure 2 is a flowchart illustrating a method performed by the UPF device 120 in the communication network 100. The method comprises a first step 210 which is receiving traffic packets from a communication device 105 via the RAN device 110 of the communication network. The method further comprises a determining step 220, wherein it is determined if the traffic packets received from the communication device are comprising at least one anomalous traffic packet. In a sending step 230 a first message is sent to the RAN device in response to an anomaly determination that at least one anomalous traffic packet has been received, wherein the first message comprises a first indication for a release of a user data tunnel associated with the communication device.

[0084] The invention or any of its embodiments provides advantages. For example, the determining step 220 may address the challenges of consuming resources, such as the AMF device and / or the SMF device, to process the incoming traffic packets before the UPF device examines the incoming traffic packets by enabling the determination of whether the traffic packets received by the communication device include at least one anomalous traffic packet before the traffic packets are optionally forwarded to the network 130. The sending step 230 of a first message to the RAN device, in response to anomaly determination that at least one anomalous traffic packet has been received, is provided to address the challenge of blocking the generation of new traffic packets before the resources are consumed, by indicating the release of the user data tunnel associated with the communication device is provided.

[0085] Figure 3 is a flowchart illustrating a method 300 performed by the RAN device 110 of the communication network 100. The method comprises a step 310 of receiving the first message from the UPF device 120 in the communication network, wherein the first message comprises the first indication for the release of the user data tunnel associated with the communication device 105. In response to receiving the message the method may comprise a step 320 of blocking traffic packets from the communication device, and / or a step 330 of releasing user data tunnels associated with the communication device.

[0086] The receiving step 310 may enable blocking of anomalous traffic packets and / or releasing user data tunnels by the RAN device based on the indication for the release of user data tunnels associated with a communication device before triggering of session release associated with the communication device. The blocking 320 and / or releasing 330 steps enable the further flow of packet traffic with the communication device to be blocked and the utilization of resources to be improved in the event of an attack.

[0087] Figure 4 is a flowchart illustrating a method 400 performed by the AMF device 140 in the communication network 100. The method comprises a step 410 of receiving a second message from the RAN device 110 in the communication network, wherein the message comprises the first indication for the release of the user data tunnel associated with the communication device 105. The method further comprises a step 420 of sending to the UDM device 170 in the communication network, a request for deregistration of the AMF device in response to receiving the second message, wherein the request comprises the first indication for the release of the user data tunnel associated with the communication device.

[0088] Step 410 and step 420 may address the challenge of enabling deregistration of the AMF device after releasing of the user data tunnels and / or blocking traffic packets by the RAN device, leading to increased security for the communication network and controllability in an attack situation. Step 410 and step 420 further enables an improved deregistration process during an attack situation, as resources are being preserved. In addition, the sessions associated with the communication device can be released in a time-efficient manner.

[0089] Figure 5 is a flowchart illustrating a method 500 performed by the UDM device 170 in the communication network 100. The method comprises a step 510 of receiving from the AMF device in the communication network a request for deregistration of the AMF device, wherein the request comprises the first indication for the release of the user data tunnel associated with the communication device. The method comprises further a step 520 of denying access of the communication device to the communication network in response to receiving the request for deregistration.

[0090] Step 510 and step 520 may address the challenge of blocking generation of further anomalous traffic packets associated with the communication device and avoid continuous detection block task. Denying access of the communication device to the communication network improves the continuous load of the resources and increases safety in an attacking situation, which enables preventing the communication device from establishing a new session with the communication network.

[0091] The method 200, 300, 400 and 500 therefore enables for avoiding an overloading of the network functions in the core network 190, i.e. , the resources in the core network, or in the RAN device due to an attack. By indicating the release of the user data tunnel associated with the communication device after determination, reduced load on the resources such as the RAN device and the core network are enabled. The anomalous traffic packets are enabled to get blocked at the origin of the flow of traffic packets, which leads to reduced overload scenarios of the resources. Further, by first releasing the user data tunnel associated to the communication device, and then propagating the indication to the AMF device, SMF device and / or UDM device(s) for updating a session related to the communication device, a reduction of the time period to block anomalous traffic packets and avoid further generation of anomalous traffic packets is enabled. The invention enables improved safety for the communication network and allows for higher controllability of attacks (such as a DDoS attack or fraudulent flows) by avoiding overload of resources, reducing the time period to block the anomalous traffic packets and / or avoiding further generation of anomalous traffic packets related to the communication device.

[0092] Figures 6A to 6D are signaling diagrams of an exemplary interaction between the communication device 105, the RAN device 110, the AMF device 140, the SMF device 150, the PCF device 180, the UPF device 120, the UDM device 170, the UDR device 160 and the network 130. In figures 6A to 6D the communication device, the RAN device, the AMF device, the SMF device, the PCF device, the UPF device, the UDM device, the UDR device and the network are depicted for illustration, even if not all entities are comprised in the interaction of each (sub-)figure 6A to 6D. The entities not comprised in the interaction of a sub-figure is not limiting the interaction flow of each sub-figure 6A to 6D.

[0093] In an optional step 601 of figure 6A the SMF device sends an association setup request to the UPF.

[0094] The UPF device receives the association setup request from the SMF device in the communication network 100.

[0095] In an example the association setup request is a packet forwarding control protocol, PFCP, association setup request. In a further example the association setup request is a request to indicate the capabilities of the UPF.

[0096] In one example, the SMF device initiates an association setup procedure that is used to establish the association between the SMF device and the UPF device so that the SMF device can subsequently use the resources of the UPF device, i.e., establish sessions such as sessions related to a control protocol. In an example the session associated to a control protocol is a PFCP session. In an optional step 602 the UPF device sends a response related to the association setup request to the SMF device, wherein the response comprises a report of at least one, UPF device, capability.

[0097] The SMF device receives the response related to the association setup request. The response is for example a PFCP association setup response or an acknowledgement, which comprises optionally a set of features in the UPF device and optionally available user plane resources. The set of features may be for example UPF device features. Features indicate a capability of the UPF device supported by the UPF. The report is, for example, a list of at least one UPF device capability.

[0098] In an embodiment, the at least one UPF device capability comprises a feature, wherein the feature comprises at least one of a user data tunnel release feature and an anomaly determination feature. This may enable the SMF device to identify that the UPF device of a group of UPFs support the capability of a user data tunnel release feature or an anomaly determination feature. Further, it enables that the SMF device may select a UPF device supporting the feature on session associated with the control plane basis, such as a PFCP session basis.

[0099] The anomaly determination feature may indicate that the UPF device supports detecting anomalous traffic packets. In an example the anomaly determination feature is an anomaly detection feature.

[0100] The user data tunnel release feature may indicate that the UPF device supports sending an indication for a release of a user data tunnel, such as for example GTP-U tunnel, associated with the communication device. In an example the UPF device supports sending an indication for the release of the user data tunnel in response to an anomaly determination.

[0101] In table 1 examples of features supported by the UPF device are listed.

[0102] Table 1 : Examples of features supported by the UPF device.

[0103] The user data tunnel release feature may be enables / disabled by for example the MNO on a per subscriber, on a per group of subscribers, on a per global (network) basis or an a per data network name (DNN) basis.

[0104] Referring to figure 6A, in an optional step 603 the communication device may send a session establishment request to the AMF device via the RAN device.

[0105] The AMF device receives the session establishment request from the communication device via the RAN device.

[0106] The RAN device receives the session establishment request from the communication device and forwards the session establishment to the AMF device via for example a N1 interface.

[0107] The session establishment request may trigger the AMF device to establish a session associated to the communication device.

[0108] In an example the session establishment request is a protocol data unit (PDU) session establishment request, and / or the session associated to the communication device is a PDU session.

[0109] In an optional step 604, the AMF device selects, in response to receiving the session establishment request, the SMF.

[0110] In an optional step 605, the AMF device sends a session create message to the SMF. The SMF device may receive the session create message. In an example, the session create message triggers the SMF device to establish the session associated to the communication device. In an example, the session create message is a Nsmf_PDU_Session_Create message.

[0111] In an example, the AMF device sends a subscribe request associated with a set of subscription data to the UDM device. In this example, the UDM device receives a subscribe request associated with a set of subscription data, and in response to receiving the AMF's subscribe request, the UDM device subscribes the AMF device to the set of subscription data. Subscribing may comprise, sending by the UDM device may a subscribe request associated with the set of subscription data to the UDR. The UDM device may receive a subscribe response associated with the set of subscription data. The subscribe response associated with the set of subscription data is for example an acknowledgment of subscription to at least part of the set of subscription data. At least a part of the set of subscription data may comprise, for example, the entire set of subscription data, or a first part of the set of subscription data relating to the UDM device, and / or a second part of the set of subscription data relating to the UDR device function. The UDM device may send the subscribe response associated with the set of subscription data to the AMF. In this example, the AMF device can receive the subscribe response associated with the set of subscription data. The subscribe response associated with the set of subscription data is for example an acknowledgment of subscription to at least part of or all the set of subscription data. In an example the subscription to the set of subscription data relates to enabling a mechanism to get notified when there are changes in at least part of or all the set of subscription data. The set of subscription data relates to changes in the UDR. In an example the set of subscription data is UDR device data.

[0112] In an optional step 606, the SMF device selects the PCF. In an optional step 607, the SMF device sends, to the PCF device, a first request message to retrieve policies for the session associated to the communication device. The policies relate to for example, at least one of a session management policy, mobility management policy and connection management policy. In an example, policies relate to policy data relating to at least one of a session management policy, mobility management policy and connection management policy. The PCF device may receive the first request message to retrieve policies for the session associated to the communication device from the SMF. In an example the first request message to retrieve session policies is a Npcf_SMPolicyControl_Create request message. In an example the session policies are session management policies.

[0113] In an optional step 608, the PCF device sends a second request message to retrieve the policies for the session associated with the communication device to the UDR. Step 608 enables that the PCF device triggers to retrieve subscription data. In an example the second request message to retrieve the policies is a Nudr_Query request message. Policies for the session associated with the communication device may be traffic handling policies, e.g., traffic steering, reporting, Quality of Service (QoS), on a per application basis, etc..

[0114] In an optional step 609, the PCF device receives a second response message comprising policies for the session associated to the communication device from the UDR device, wherein the response comprises at least one of an anomaly determination policy and a user data tunnel release policy. In an example the anomaly determination policy is an anomaly detection policy. In an example the second response message from the UDR device is a Nudr_Query response message. In a further example the anomaly determination policy and / or user data tunnel release policy is a subscription policy, wherein the anomaly determination policy relates to the anomaly feature of a UPF device of the group of UPFs, and the user data tunnel release policy relates to a user data tunnel release feature of the UPF device of a group of UPFs.

[0115] In an alternative example to step 608 and 609, the PCF device may store the policies, comprising at least one of an anomaly determination policy and a user data tunnel release policy.

[0116] In an optional step 610, the PCF device sends a first response message related to the first request message to the SMF device, wherein the response comprises at least one of an anomaly determination policy and a user data tunnel release policy. The SMF device receives the first response related to the first request message from the PCF device, wherein the response comprises at least one of an anomaly determination policy and a user data tunnel release policy. This may enable that the SMF device selects the UPF device based on the policies.

[0117] In an example the first response is a Npcf_SMPolicyControl_Create response. In a further example the first response comprises policy and charging control (PCC) rules for the session associated with the communication device.

[0118] In an optional step 611 , the SMF device selects the UPF device, supporting the anomaly determination policy and the user data tunnel release policy. In an example, the SMF device selects the UPF device of a group of UPFs supporting the anomaly determination feature and the user data tunnel release feature. In case there is no UPF device supporting the anomaly determination policy and / or the user data tunnel release policy the SMF device may send an indication to the PCF device, wherein the indication comprises an information that the policies cannot be met.

[0119] In an optional step 612, the SMF device sends a session establishment request to the UPF device, wherein the session establishment request comprises at least one of the anomaly determination policy and the user data tunnel release policy. The UPF device receives the session establishment request from the SMF device in the communication network, wherein the session establishment request comprises at least one of the anomaly determination policy and the user data tunnel release policy. The session establishment request may be a packet forwarding control protocol (PFCP) session establishment request or a PFCP session modification request. The session establishment request, for example, relates to a request for establishing a session related to the control plane. In a further example, the session establishment request relates to a request for modification of the session related to the control plane.

[0120] In an example, the user data tunnel release policy may apply to each session associated with the control plane. In the example, a protocol that applies to the session associated with the control plane includes an indication for the user tunnel release policy in the session establishment request. For example, the user plane tunnel release policy is a GTP-U tunnel release policy that applies to any PFCP session. In this example, the protocol is a PFCP protocol that includes an indication such as an information element for the GTP-U tunnel release policy in the PFCP session setup request. In the case of the example that the user data tunnel release policy is a GTP-ll tunnel release policy, the GTP-ll tunnel release policy may apply on a PFCP session basis. In this case, a PFCP protocol includes an indication of the GTP-ll tunnel release policy in a PFCP Session Establishment / Modification Request message.

[0121] The UPF device may initiate the association setup procedure to set up the session associated to the control plane based on the session establishment request.

[0122] In an optional step 613, the UPF device is sending a response related to the session establishment request to the SMF. In an example, the response related to the session establishment request is an acknowledgement of the request and / or an acknowledgment for setting up the session associated to the control plane. In an example the acknowledgment of the request comprises an indication of acceptance corresponding to the session establishment request.

[0123] Referring to figure 6B, which shows the optional steps 614 to 619, continuous traffic packet flows from the communication device to the communication network and from the communication network to the communication device.

[0124] A traffic packet is for example an Internet Protocol (IP) packet. A set of traffic packets comprising at least one traffic packet relates to traffic data.

[0125] In the optional step 614, the communication device sends at least one traffic packet to the RAN. The RAN device receives the traffic packet from the communication device. In the optional step 615, the RAN device sends the traffic packet to the UPF. The UPF device receives the traffic packet from the RAN. In an optional step 616, the UPF device sends the traffic packet to the network. The network receives the traffic packet from the UPF. In the optional step 617, the network sends at least one traffic packet to the UPF. The UPF device receives the traffic packet from the network. In the optional step 618, the UPF device sends the traffic packet, received from the network to the RAN. The RAN device receives the traffic packet from the UPF. In the optional step 619, the RAN device sends the traffic packet, received from the UPF device, to the communication device.

[0126] In an embodiment, the RAN device forwards the traffic packets between the communication device and the UPF. In an embodiment, the UPF device forwards the traffic packets between the RAN device and the network. The steps 614 to 619 may be repeated, wherein the traffic packets are sent to achieve a continuous traffic packet flow between the communication device and the communication network.

[0127] In a step 620, the UPF device determines if the traffic packets received from the communication device are comprising at least one anomalous traffic packet. An anomalous traffic packet may be for example a fraudulent traffic packet and / or a traffic packet related to a DoS or DDoS attack. This may enable determination of anomalous traffic packets before consuming resources in the communication network. In an example, step 620 is performed between step 615 and 616. Determining may comprise the UPF device inspecting or checking the traffic packet.

[0128] In an example, the traffic packet is a fraudulent traffic packet relating to a domain name system (DNS) traffic flow. In this example, determining may comprise inspecting the DNS traffic flow and / or checking a DNS query towards a domain resulting in a list of at least one server internet protocol (IP) address. In the example, the UPF device may further check whether there is a subsequent connection, such as a transmission control protocol (TCP) connection, towards at least one of the server IP addresses. Alternatively, or additionally, the UPF device may check whether a subsequent transport layer security (TLS) Client Hello server name indication (SNI) field relates towards one of the server IP addresses. In case there is no TLS client Hello SNI field relating towards at least one of the server IP addresses or there is no subsequent connection towards at least one of the server IP addresses, the UPF device determines anomaly that at least one anomalous traffic packet has been received, in this example that the traffic packet is fraudulent.

[0129] In a second example, the traffic packet relates to a DoS or DDoS attack. In this second example determining comprises inspecting more than one traffic packets received via the RAN device from the communication device. In case the number of traffic packets exceed a threshold, the traffic packets are considered anomalous. For example, the threshold is preconfigured within the UPF device and is, e.g., 50 traffic packets per second. In this example, in case the number of traffic packets exceed more than 50 traffic packets per second, the traffic packets relate to a DoS or DDoS attack. In response to an anomaly determination that at least one anomalous traffic packet has been received, the UPF device sends in a step 230 a first message to the RAN device, wherein the first message comprises a first indication for a release of a user data tunnel associated with the communication device. In an embodiment, the at least one anomalous traffic packet comprises the at least one fraudulent traffic packet and / or a set of traffic packets related to the DoS attack or DDoS attack.

[0130] In an example, the first message is a message and the first indication is an indication. The first message is for example, an End Marker GTP-U Message, comprising the first indication. In an example, the first indication relates to an information element (IE). The IE may be for example a GTP-U tunnel release for release of all GTP-U tunnels or at least one GTP-U tunnel related to the communication device, such as GTP-U tunnels related to the subscription permanent identifier (SUPI) relating to the communication device. In a further example, the first indication is to indicate that at least one or all user data tunnels are to be released.

[0131] In a further example, the first message is a trigger message configured to trigger the RAN device to block traffic packets from the communication device, and / or release user data tunnels associated with the communication device.

[0132] In an embodiment the first message comprises a second indication of an anomaly determination. In an example the first indication comprises the second indication. The second indication of anomaly determination is, e.g., an IE indicating the determination of anomalous traffic packets. In a further example the second indication is the first indication, wherein the first indication relates to a user data tunnel release due to anomaly determination, such as GTP-U tunnel release due to anomaly determination and / or to an IE. In table 2 an example of lEs within the End Marker GTP-U message is listed.

[0133] Table 2: Example of Information Element (IE).

[0134] The RAN device receives the first message from the UPF device in the communication network, wherein the first message comprises the first indication for a release of a user data tunnel associated with the communication device. This may enable triggering the RAN device to close the user data tunnels related to the communication device or to block traffic packets from the communication device.

[0135] In an example the UPF device releases the user data tunnels on the UPF device side related to the communication device.

[0136] In a step 622, in response to receiving the message, the RAN device blocks traffic packets from the communication device and / or releases the user data tunnels associated with the communication device. This may enable preventing the communication device from sending traffic packets before resources in the communication network processed the anomalous traffic packets. In an example step 622 comprises that the RAN device does stop sending traffic packets stored in the RAN device buffers and / or stop sending traffic packets in a transit at an air interface between the RAN device and the communication device. Step 622 further comprises, for example, deleting any buffered data by the RAN device associated with the communication device, such as the SlIPI related to the communication device.

[0137] Releasing the user data tunnels associated with the communication device comprises for example, closing the RAN device side of all the user data tunnels associated with the communication device, such as the SLIPI related to the communication device. This may enable that all user data tunnels associated to the communication device are released immediately. The user data tunnels associated with the communication device may be the user data tunnels related to the communication device or SLIPI related to the communication device.

[0138] Blocking traffic packets from the communication device comprises for example, denying uplink slots for the transmission of the communication or sending an indication to the communication device for a stop of transmission of traffic packets through the air interface between the RAN device and the communication device.

[0139] In an optional step 623, the RAN device sends a second message to the AMF device in the communication network, wherein the second message comprises the first indication. This may enable that the sessions related to the communication device and the control plane can be released and the information of an attack is propagated. The AMF device receives the second message from the RAN device in the communication network, wherein the second message comprises the first indication for the release of the user data tunnel associated with the communication device.

[0140] In an embodiment the second message comprises the second indication of the anomaly determination. In an example, the first indication comprises the second indication.

[0141] In an example, the IE comprised in the first message is comprised in the second message. In a further example the second message comprises an indication that the user data tunnel has been released and / or that a resource related to the session associated with the communication device has been released. The second message may further comprise a trigger to release the session associated with the communication device. In an example the second message is a N2 message comprising the ID of the session associated with the communication device, such as the PDU session ID and / or Session Management (SM) information. The second message may be a message sent via an N2 interface.

[0142] In an optional step 624, the AMF device sends a third message to the RAN device indicating to release all resources of a session associated with the communication device. The RAN device receives the third message from the AMF device in the communication network.

[0143] In an embodiment, the third message is configured to prevent the communication device to send traffic packets to the communication network. In an example, the third message is a N1 non-access stratum (NAS) message, such as a SM container message and / or a PDU session release command. In a further example the third message is a message to release all associated resources to the session associated to the communication network. The third message may be a message sent via an N1 interface. Receiving the third message by the RAN device triggers the RAN device to release all resources of a session associated with the communication device.

[0144] In an optional step 625, the RAN device forwards the third message to the communication device, wherein the third message indicates that all resources of a session associated with the communication device are to be released by the RAN. Step 625 enables that the communication device is not able to generate and send new traffic packets to the communication network via the session associated with the communication device. This way the generation of new traffic by the communication device is blocked. Releasing by the RAN device comprises releasing the communication device context, as e.g., stored in RAN device memory.

[0145] In an optional step 626, referring to figure 6C, the AMF device sends, in response to receiving the second message, an unsubscribe request associated with the set of subscription data to the UDM device. The unsubscribe request associated with the set of subscription data may be a Nudm_SDM_Unsubscribe_request message. The UDM device receives the unsubscribe request associated with the set of subscription data. In response to receiving the unsubscribe request of the AMF device, the UDM device unsubscribes the AMF device from at least a part of the set of subscription data in an optional step 627. In an example unsubscribing the AMF device by the UDM device comprises set 628 to 631 .

[0146] In an optional step 628, the UDM device sends an unsubscribe request associated with the set of subscription data to the UDR device in the communication network. The unsubscribe request associated with the set of subscription data is for example a Nudr_DM_Unsubscribe_request message. The UDR device receives the unsubscribe request associated with the set of subscription data. The UDR device unsubscribes the UDM device, in an optional step 629, from at least a part of the set of subscription data. The UDR device sends, in an optional step 630, an unsubscribe response associated with the set of subscription data. The unsubscribe response associated with the set of subscription data is for example a Nudr_DM_Unsubscribe_request message. The UDM device receives from the UDM device the unsubscribe response associated with the set of subscription data.

[0147] In an optional step 631 , the UDM device sends, to the AMF device, an unsubscribe response associated with the set of subscription data. The unsubscribe response associated with the set of subscription data is for example a Nudm_SDM_Unsubscribe_response. In an example step 631 is performed before step 628.

[0148] In response to receiving the second message, the AMF device sends in a step 632 to the UDM device in the communication network, a request for deregistration of the AMF device, wherein the request comprises the first indication for the release of the user data tunnel associated with the communication device. In an example the request for deregistration is a Nudm_UECM_Deregistration_request message. In a further example the request for deregistration comprises the SlIPI of the communication device, an Access Type and an ID of the AMF. The UDM device receives from the AMF device in the communication network the request for deregistration of the AMF device, wherein the request comprises the first indication for the release of the user data tunnel associated with the communication device.

[0149] In an embodiment, the request comprises the second indication of an anomaly determination. In an example, the first indication comprises the second indication.

[0150] In an example, the IE comprised in the first message and / or second message is comprised in the request. In a further example the request comprises an indication that the user data tunnel has been released and / or that the session associated with the communication device is to be released.

[0151] In response to receiving the request for deregistration of the AMF device the UDM device denies the access of the communication device to the network. Denying may optionally comprise at least one of the steps 633 to 635.

[0152] In the optional step 633, the UDM device sends an update message to the UDR device in the communication network. The update message is, for example, a Nudr_DM_Update message. In an example, the update message comprises the SUPI related to the communication device.

[0153] In the optional step 634 shown in figure 6D, the UDR device modifies the subscription data associated to the communication device. In an example, the subscription data associated to the communication device is related to the SUPI subscription of the communication device.

[0154] In an embodiment, modifying the subscription data associated to the communication device comprises changing the subscription data associated to the communication device to denied. This enables, that the communication device is not allowed to create new sessions associated to the communication device such as PDU session. Changing the subscription data associated to the communication device may be for example done for a period of time. The period of time may be preconfigured based on the anomaly type or on the severity of the attack. In an alternative step, the UDR device may update a context of the communication device to a release of session associated to the communication device status. This enables that the communication device is able to create new sessions associated to the communication device. The UPF device may determine based on severity of the attack whether to change the subscription data to denied or update the context of the communication device. In this example, the type of anomaly is indicated in, e.g., the first indication.

[0155] In an example, the communication devices context is changes to release the session after determination of the first determination of anomalous traffic packets. In this example the communication device may establish a new session associated to the communication device. Once the UPF device detects a second time anomalous traffic packets associated with the communication device, the UDR device may change the subscription data associated with the communication device to denied.

[0156] In an embodiment, the UDR device may send a response message to the update message to the UDM device. The UDM device receives the response message to the update message. The response message may be for example an acknowledgment message for indicating of successful modification of subscription data and / or a Nudr_DM_Update_response message.

[0157] In an optional step 635 the UDM device sets a communication device purged flag associated with the access type. Setting a communication device purged flag refers to an indication to remove the subscription data.

[0158] In an optional step 636 the UDM device sends to the AMF device a response related to the request of deregistration of the AMF. The response related to the request of deregistration may be for example a Nudm_UECM_Deregistration_response. The AMF device receives, from the UDM device the response related to the request for deregistration of the AMF.

[0159] In an optional step 637, the UDM device sends a session release request to the SMF. This may enable triggering the SMF device for releasing the remaining resources of the session associated to the communication device. In an example the session release request may be a Nsmf_PDUSession_ReleaseSMContext service operation. In a further example the session release request is a request to release the session associated to the communication device. The SMF device receives the session release request from the UDM device. In an example the SMF device releases the remaining resources of the session associated to the communication device. In an alternative embodiment the AMF device sends a session release request to the SMF.

[0160] In an optional step 638, the SMF device sends a session release response to the UDM device. In an example the session release response may be a Nsmf_PDUSession_ReleaseSMContext response operation. In a further example the session release response comprises an indication that the remaining resources are released relating to the session associated to the communication device. The UDM device receives, the session release response from the SMF. In an alternative embodiment the SMF device sends the session release response to the AMF.

[0161] In an optional step 639, the SMF device sends a deletion notification to the UPF. The UPF device receives the deletion notification from the SMF. In an example the deletion notification indicates the deletion by the SMF device of the session associated with the control plane. In an example the deletion notification comprises the notification of deletion of the PFCP Session.

[0162] Figure 7 is a flowchart illustrating embodiments of the method 700 performed by the UPF device 120.

[0163] In an embodiment, steps 710 to 740 may be performed to enable a traffic packet flow between the communication device 105 and the network 130 via the RAN device 110.

[0164] In the optional step 710, the UPF device is receiving the association setup request from the SMF device 150 in the communication network 100. This step 710 relates to step 601 of figure 6A.

[0165] In the optional step 720, the UPF device is sending the response related to the association setup request to the SMF device, wherein the response comprises the report of at least one user plane function, UPF, device capability. This step 720 relates to step 602 of figure 6A. In an embodiment, the UPF device capability comprises the feature, wherein the feature comprises at least one of the user data tunnel release feature and the anomaly determination feature.

[0166] In the optional step 730, the UPF device receives the session establishment request from the SMF device in the communication network, wherein the session establishment request comprises the at least one of an anomaly determination policy and the user data tunnel release policy. This step 730 relates to step 612 of figure 6A.

[0167] In the optional step 740, the UPF device sends the response related to the session establishment request to the SMF. This step 740 relates to step 613 of figure 6A.

[0168] In the optional step 750, the UPF device forwards traffic packets between the RAN device and the network 130. This step 750 relates to step 615 to 618 of figure 6B. Forwarding may comprise receiving traffic packets from the RAN device and sending traffic packets to the network and / or receiving traffic packets from the network and sending traffic packets to the RAN.

[0169] In a step 760, the UPF device receives traffic packets from the communication device 105 via the RAN device from the communication network. This step 760 relates to step 615 of figure 6B.

[0170] In a step 770, the UPF device determines if the traffic packets received from the communication device are comprising the at least one anomalous traffic packet. This step 770 relates to step 620 of figure 6B.

[0171] In a step 780, in response to the anomaly determination that at least one anomalous traffic packet has been received, the UPF device sends the first message to the RAN device, wherein the first message comprises the first indication for the release of the user data tunnel associated with the communication device. This step 780 relates to step 620 of figure 6B.

[0172] In an embodiment, the first message is configured to trigger the RAN device to block traffic packets from the communication device, and / or release user data tunnels associated with the communication device, and / or send the second message to the AMF device 140 in the communication network, wherein the second message comprises the first indication.

[0173] In an embodiment, the second message is configured to trigger the AMF device to send the request for deregistration of the AMF device to the UDM device 170, in the communication network, wherein the request comprises the first indication.

[0174] In an embodiment, the request is configured to trigger the UDM device 170 in the communication network to deny access of the communication device to the communication network.

[0175] In an embodiment, the first message and / or the second message and / or the request comprises the second indication of the anomaly determination.

[0176] In an embodiment, the at least one anomalous traffic packet comprises the at least one fraudulent traffic packet and / or the set of traffic packets related to the Denial-of- service, DoS, attack.

[0177] In an optional step 790, the UPF device receives the deletion notification from the SMF device 150 in the communication network. This step 790 relates to step 639 of figure 6D.

[0178] Figure 8 is a flowchart illustrating embodiments of the method 800 performed by the RAN device 110 of the communication network 100.

[0179] In an optional step 810, the RAN device is forwarding traffic packets between the communication device 105 and the UPF device 120. This step 810 relates to step 614, 615, 618 and / or 619.

[0180] Forwarding may comprise receiving traffic packets from the communication device and sending to the UPF device and / or receiving traffic packets from the UPF device and sending to the communication device.

[0181] In a step 820, the RAN device receives the first message from the UPF device in the communication network, wherein the first message comprises the first indication for the release of the user data tunnel associated with the communication device. This step 820 relates to step 622 of figure 6B. In a step 830, the RAN device, in response to receiving the message, blocks traffic packets from the communication device. This step 830 relates to step 623 of figure 6B.

[0182] In a step 840, which may be additionally or alternatively performed to 830, the RAN device, in response to receiving the message, releases user data tunnels associated with the communication device. This step 840 relates to step 623 of figure 6B.

[0183] In an optional step 850, the RAN device sends the second message to the AMF device 140 in the communication network, wherein the second message comprises the first indication.

[0184] In an embodiment, the second message is configured to trigger the AMF device in the communication network to send the request for deregistration of the AMF device to the UDM device 170 in the communication network, wherein the request comprises the first indication.

[0185] In an embodiment, the request is configured to trigger the UDM device to deny access of the communication device to the communication network.

[0186] In an embodiment the first message and / or a second message and / or the request comprises the second indication of the anomaly determination.

[0187] In an embodiment, blocking traffic packets associated with the communication device comprises, denying uplink slots for uplink transmission of traffic packets from the communication device.

[0188] In an optional step 860, the RAN device receives the third message, from the AMF device 140 in the communication network. This step 860 relates to step 624 in figure 6B.

[0189] In an optional step 870, the RAN device forwards the third message to the communication device, and wherein the third message indicates that all resources of the session associated with the communication device are to be released by the RAN. This step 870 relates to step 625 of figure 6B.

[0190] Figure 9 is a flowchart illustrating embodiments of the method 900 performed by the AMF device 140 of the communication network 100. In an embodiment, steps 910 to 930 enable creating the session relating to the communication device.

[0191] In the optional step 910, the AMF device receives the session establishment request from the communication device via the RAN. This step relates to step 603 of figure 6A.

[0192] In the optional step 920, in response to receiving the session establishment request, the AMF device selects the SMF device 150. This step 910 relates to step 604 of figure 6A.

[0193] In the optional step 930, the AMF device sends the session create message to the SMF. This step 930 relates to step 605 of figure 6A.

[0194] In an embodiment the wherein the session create message is configured to trigger the SMF device to the PCF device 180 in the communication network, send the first request message to retrieve policies for the session associated to the communication device to the PCF device, receive the first response related to the first request message from the PCF device, wherein the response comprises at least one of the anomaly determination policy and the user data tunnel release policy, and select the UPF device 120 supporting the at least one of the anomaly determination policy and the user data tunnel release policy.

[0195] In an embodiment the request triggers the PCF device to send the second request message to retrieve the policies for the session associated to the communication device to the UDR device 160 and receive the second response message comprising the policies for the session associated to the communication device from the UDR device, wherein the response comprises at the least one of the anomaly determination policy and the user data tunnel release policy.

[0196] In a step 940, the AMF device receives the second message from the RAN device 110, in the communication network, wherein the second message comprises the first indication for the release of the user data tunnel associated with the communication device. This step 940 relates to step 623 of figure 6B. In an optional step 950, the AMF device sends via the RAN device to the communication device the third message indicating to release all resources of the session associated with the communication device. This step 950 relates to step 624 of figure 6B.

[0197] In an embodiment, the third message is configured to prevent the communication device to send traffic packets to the communication network.

[0198] In an optional step 960, the AMF device, in response to receiving the second message, sends the unsubscribe request associated with the set of subscription data to the UDM device. This step 960 relates to step 626 of figure 6C.

[0199] In an optional step 970, the AMF device receives the unsubscribe response associated with the set of subscription data from the UDM device. This step 970 relates to step 631 of figure 6C.

[0200] In a step 980, in response to receiving the second message, the AMF device sends, the UDM device 170 in the communication network, the request for deregistration of the AMF device, wherein the request comprises the first indication for the release of the user data tunnel associated with the communication device. This step 980 relates to step 632 of figure 6C.

[0201] In an embodiment, the second message and / or the request comprises the second indication of the anomaly determination.

[0202] In an embodiment, the request is configured to trigger the UDM device to deny access of the communication device to the communication network.

[0203] In an optional step 990, the AMF device receives from the UDM device, the response related to the request for deregistration of the AMF. This step 990 relates to step 636 of figure 6D.

[0204] Figure 10 is a flowchart illustrating embodiments of the method 1000 performed by the UDM device 170 of the communication network 100.

[0205] In an optional step 1010, the UDM device receives receiving the unsubscribe request associated with the set of subscription data from the AMF. This step 1010 relates to step 626 of figure 6C. In an optional step 1020, in response to receiving the unsubscribe request of the AMF device the UDM device unsubscribes the AMF device from the set of subscription data. The step 1020 relates to step 627 of figure 6C.

[0206] In an optional step 1030, the UDM device sends to the UDR device in the communication network, the unsubscribe request associated with the set of subscription data. This step 1030 relates to step 628 of figure 6C.

[0207] In an optional step 1040, the UDM device receives from the UDR device the unsubscribe response associated with the set of subscription data. This step 1040 relates to step 629 of figure 6C.

[0208] In an optional step 1050, the UDM device sends, to the AMF device, the unsubscribe response associated with the set of subscription data. This step 1050 relates to step 630 of figure 6C. In an embodiment, step 1050 may be performed before step 1040.

[0209] In a step 1060, the UDM device receives, the AMF device 140, in the communication network, the request for deregistration of the AMF device, wherein the request comprises the first indication for the release of the user data tunnel associated with the communication device. This step 1060 relates to step 632 of figure 6C.

[0210] In a step 1070, the UDM device, in response to receiving the request for deregistration of the AMF device, denies access of the communication device to the communication network. This step 1070 relates to steps 633 of figure 6C. In an embodiment, the request comprises the second indication of the anomaly determination. In an embodiment, denying the communication device access to the communication network comprises sending the update message to the UDR device 160, in the communication network. This embodiment relates to step 633 in figure 6C. In an embodiment, denying the communication device access to the communication network comprises receiving the response to the update message from the UDR device in the communication network. This embodiment relates to step 633 in figure 6C. In an embodiment the update message is configured to trigger the UDR device to modify subscription data associated with the communication device. This embodiment relates to step 634 of figure 6D. In an embodiment modifying the subscription data associated to the communication device comprises changing the subscription data associated to the communication device to denied. In an optional step 1080, the UDM device sets the communication device purged flag associated with the access type. This step 1080 relates to step 635 in figure 6D.

[0211] In an optional step 1090, the UDM device sends to the AMF device the response related to the request of deregistration of the AMF. This step 1090 relates to step 636 in figure 6D.

[0212] In an optional step 1100, the UDM device sends session release request the SMF device 150. This step 1100 relates to step 637 in figure 6D.

[0213] In an optional step 1110, the UDM device receives the session release response from the SMF. This step 1110 relates to step 638 in figure 6D.

[0214] Figure 11 shows an example of a communication system 11100 in accordance with some embodiments.

[0215] In the example, the communication system 11100 includes a communication network 100 that includes an access network 11104, such as a radio access network (RAN) 110, and a core network 190, which includes one or more core network nodes 11108. The access network 11104 includes one or more access network nodes, such as network nodes 11110A and 11110B (one or more of which may be generally referred to as network nodes 11110), or any other similar 3rdGeneration Partnership Project (3GPP) access nodes or non-3GPP access points. Moreover, as will be appreciated by those of skill in the art, a network node is not necessarily limited to an implementation in which a radio portion and a baseband portion are supplied and integrated by a single vendor. Thus, it will be understood that network nodes include disaggregated implementations or portions thereof. For example, in some embodiments, the communication network 100 includes one or more Open-RAN (ORAN) network nodes. An ORAN network node is a node in the telecommunication network QQ102 that supports an ORAN specification (e.g., a specification published by the O-RAN Alliance, or any similar organization) and may operate alone or together with other nodes to implement one or more functionalities of any node in the communication network 100, including one or more network nodes 11110 and / or core network nodes 11108.

[0216] Examples of an ORAN network node include an open radio unit (O-RU), an open distributed unit (O-DU), an open central unit (O-CU), including an O-CU control plane (O-CU-CP) or an O-CU user plane (O-CU-UP), a RAN intelligent controller (near-real time or non-real time) hosting software or software plug-ins, such as a near-real time control application (e.g., xApp) or a non-real time control application (e.g., rApp), or any combination thereof (the adjective “open” designating support of an ORAN specification). The network node may support a specification by, for example, supporting an interface defined by the ORAN specification, such as an A1 , F1 , W1 , E1 , E2, X2, Xn interface, an open fronthaul user plane interface, or an open fronthaul management plane interface. Moreover, an ORAN access node may be a logical node in a physical node. Furthermore, an ORAN network node may be implemented in a virtualization environment (described further below) in which one or more network functions are virtualized. For example, the virtualization environment may include an O-Cloud computing platform orchestrated by a Service Management and Orchestration Framework via an 0-2 interface defined by the 0-RAN Alliance or comparable technologies. The network nodes 11110 facilitate direct or indirect connection of communication devices, such as user equipment (UE), such as by connecting UEs 11112A, 11112B, 11112C, and 11112D (one or more of which may be generally referred to as UEs 11112) to the core network 190 over one or more wireless connections.

[0217] Example wireless communications over a wireless connection include transmitting and / or receiving wireless signals using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for conveying information without the use of wires, cables, or other material conductors. Moreover, in different embodiments, the communication system 11100 may include any number of wired or wireless networks, network nodes, communication devices, such as UEs, and / or any other components or systems that may facilitate or participate in the communication of data and / or signals whether via wired or wireless connections. The communication system 11100 may include and / or interface with any type of communication, telecommunication, data, cellular, radio network, and / or other similar type of system.

[0218] The UEs 11112 may be any of a wide variety of communication devices, including wireless devices arranged, configured, and / or operable to communicate wirelessly with the network nodes 11110 and other communication devices. Similarly, the network nodes 11110 are arranged, capable, configured, and / or operable to communicate directly or indirectly with the UEs 11112 and / or with other network nodes or equipment in the communication network 100 to enable and / or provide network access, such as wireless network access, and / or to perform other functions, such as administration in the communication network 100.

[0219] In the depicted example, the core network 190 connects the network nodes 11110 to one or more hosts, such as host 11116. These connections may be direct or indirect via one or more intermediary networks or devices. In other examples, network nodes may be directly coupled to hosts. The core network 190 includes one more core network nodes (e.g., core network node 11108) that are structured with hardware and software components. Features of these components may be substantially similar to those described with respect to the UEs, network nodes, and / or hosts, such that the descriptions thereof are generally applicable to the corresponding components of the core network node 11108. Example core network nodes include functions of one or more of a Mobile Switching Center (MSC), Mobility Management Entity (MME), Home Subscriber Server (HSS), Access and Mobility Management Function (AMF) 140, Session Management Function (SMF) 150, Authentication Server Function (ALISF), Subscription Identifier De-concealing function (SIDF), Unified Data Management (UDM) 170, Security Edge Protection Proxy (SEPP), Network Exposure Function (NEF), and / or a User Plane Function (UPF) 120.

[0220] The host 11116 may be under the ownership or control of a service provider other than an operator or provider of the access network 11104 and / or the communication network 100, and may be operated by the service provider or on behalf of the service provider. The host 11116 may host a variety of applications to provide one or more service. Examples of such applications include live and pre-recorded audio / video content, data collection services such as retrieving and compiling data on various ambient conditions detected by a plurality of communication devices, analytics functionality, social media, functions for controlling or otherwise interacting with remote devices, functions for an alarm and surveillance center, or any other such function performed by a server.

[0221] As a whole, the communication system 11100 of Figure 11 enables connectivity between the communication devices, network nodes, and hosts. In that sense, the communication system may be configured to operate according to predefined rules or procedures, such as specific standards that include, but are not limited to: Global System for Mobile Communications (GSM), Universal Mobile Telecommunications System (UMTS), Long Term Evolution (LTE), and / or other suitable 2G, 3G, 4G, 5G standards, or any applicable future generation standard (e.g., 6G), wireless local area network (WLAN) standards, such as the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standards (WiFi), and / or any other appropriate wireless communication standard, such as the Worldwide Interoperability for Microwave Access (WiMax), Bluetooth, Z-Wave, Near Field Communication (NFC) ZigBee, LiFi, and / or any low-power wide-area network (LPWAN) standards such as LoRa and Sigfox.

[0222] In some examples, the communication network 100 is a cellular network that implements 3GPP standardized features. Accordingly, the communications network 100 may support network slicing to provide different logical networks to different devices that are connected to the communication network 100. For example, the communications network 100 may provide Ultra Reliable Low Latency Communication (URLLC) services to some UEs, while providing Enhanced Mobile Broadband (eMBB) services to other UEs, and / or Massive Machine Type Communication (mMTC)ZMassive loT services to yet further UEs.

[0223] In some examples, the UEs 11112 are configured to transmit and / or receive information without direct human interaction. For instance, a UE may be designed to transmit information to the access network 11104 on a predetermined schedule, when triggered by an internal or external event, or in response to requests from the access network 11104. Additionally, a UE may be configured for operating in single- or multi-RAT or multi-standard mode. For example, a UE may operate with any one or combination of Wi-Fi, NR (New Radio) and LTE, i.e. being configured for multiradio dual connectivity (MR-DC), such as E-UTRAN (Evolved-UMTS Terrestrial Radio Access Network) New Radio - Dual Connectivity (EN-DC).

[0224] In the example, the hub 11114 communicates with the access network 11104 to facilitate indirect communication between one or more communication devices (e.g., UE 11112C and / or 11112D) and network nodes (e.g., network node 11110B). In some examples, the hub 11114 may be a controller, router, content source and analytics, or any of the other communication devices described herein regarding UEs. For example, the hub 11114 may be a broadband router enabling access to the core network QQ106 for the communication devices. As another example, the hub 11114 may be a controller that sends commands or instructions to one or more actuators in the UEs. Commands or instructions may be received from the communication devices, network nodes 11110, or by executable code, script, process, or other instructions in the hub 11114. As another example, the hub 11114 may be a data collector that acts as temporary storage for communication device data and, in some embodiments, may perform analysis or other processing of the data. As another example, the hub 11114 may be a content source. For example, for a communication device that is a VR headset, display, loudspeaker or other media delivery device, the hub 11114 may retrieve VR assets, video, audio, or other media or data related to sensory information via a network node, which the hub 11114 then provides to the communication device either directly, after performing local processing, and / or after adding additional local content. In still another example, the hub 11114 acts as a proxy server or orchestrator for the communication devices, in particular if one or more of the UEs are low energy loT devices.

[0225] The hub 11114 may have a constant / persistent or intermittent connection to the network node 11110B. The hub 11114 may also allow for a different communication scheme and / or schedule between the hub 11114 and communication devices (e.g., UE 11112C and / or 11112D), and between the hub 11114 and the core network 190. In other examples, the hub 11114 is connected to the core network 190 and / or one or more communication devices via a wired connection. Moreover, the hub 11114 may be configured to connect to an M2M service provider over the access network 11104 and / or to another UE over a direct connection. In some scenarios, UEs may establish a wireless connection with the network nodes 11110 while still connected via the hub 11114 via a wired or wireless connection. In some embodiments, the hub 11114 may be a dedicated hub - that is, a hub whose primary function is to route communications to / from the communication devices from / to the network node 11110b. In other embodiments, the hub 11114 may be a non-dedicated hub - that is, a device which is capable of operating to route communications between the UEs and network node 11110b, but which is additionally capable of operating as a communication start and / or end point for certain data channels.

[0226] Figure 12 illustrates a block diagram illustrating embodiments of the UPF device 120 in further detail. In practice, the steps 710 to 790 of the method 700 performed by the UPF device are performed by a processing circuitry 124, embodied in one or more microprocessors arranged to execute a computer program 121 that is downloaded to a computer program product 125, here in the form of a suitable computer readable storage medium 122 associated with the microprocessor, such as random access memory (RAM), read-only memory (ROM), or a non-volatile computer readable storage medium, such as flash memory or a hard disk drive, or any combination thereof. The computer program 121 comprises computer-executable instructions stored or downloaded to the memory 122 and are executable by the processing circuitry 124. Alternatively, the computer program 121 may be transferred to the storage medium 122 using a suitable computer program product, such as a memory stick or in a memory of a device. Thus, the computer program 121 may be stored in any suitable manner in the computer program product. The processing circuity 124 is arranged to cause the UPF device to carry out the steps 710 to 790 of method 700 in accordance with any of the of the described embodiments for steps 710 to 790. The processing circuitry is in one embodiment a general-purpose processor, but may alternatively be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), a complex programmable logic device (CPLD), etc. An I / O interface 123 is provided for communicating with external and / or internal entities using wired communications, e.g., based on Ethernet, and / or wireless communications, e.g., Wi-Fi, and / or a cellular network corresponding to one or a combination of 5G cellular networks, LTE, LTE-advanced, UMTS, or any other current or future wireless network, such as a future 3GPP 6G network, as long as the principles described below are applicable. The UPF device may host a core network function of the communication network, which is configured to communicate with other network functions of the communication network using 3GPP-defined protocols.

[0227] Figure 13 illustrates a block diagram illustrating embodiments of the RAN device 110 in further detail. In practice, the steps 810 to 870 of the method 800 performed by the RAN device are performed by a processing circuitry 114, embodied in one or more microprocessors arranged to execute a computer program 111 that is downloaded to a computer program product 115, here in the form of a suitable computer readable storage medium 112 associated with the microprocessor, such as random access memory (RAM), read-only memory (ROM), or a non-volatile computer readable storage medium, such as flash memory or a hard disk drive, or any combination thereof. The computer program 111 comprises computer-executable instructions stored or downloaded to the memory 112 and are executable by the processing circuitry 114. Alternatively, the computer program 111 may be transferred to the storage medium 112 using a suitable computer program product, such as a memory stick or in a memory of a device. Thus, the computer program 111 may be stored in any suitable manner in the computer program product. The processing circuity 114 is arranged to cause the RAN device to carry out the steps 810 to 870 of method 800 in accordance with any of the of the described embodiments for steps 810 to 870. The processing circuitry is in one embodiment a general-purpose processor, but may alternatively be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), a complex programmable logic device (CPLD), etc. An I / O interface 113 is provided for communicating with external and / or internal entities using wired communications, e.g., based on Ethernet, and / or wireless communications, e.g., Wi-Fi, and / or a cellular network corresponding to one or a combination of 5G cellular networks, LTE, LTE-advanced, UMTS, or any other current or future wireless network, such as a future 3GPP 6G network, as long as the principles described below are applicable. The RAN device may be part of the access network node of the communication network, which is configured to communicate with the communication device 105 and the core network 190 using 3GPP-defined protocols.

[0228] Figure 14 illustrates a block diagram illustrating embodiments of the AMF device 140 in further detail. In practice, the steps 910 to 990 of the method 900 performed by the AMF device are performed by a processing circuitry 144, embodied in one or more microprocessors arranged to execute a computer program 141 that is downloaded to a computer program product 145, here in the form of a suitable computer readable storage medium 142 associated with the microprocessor, such as random access memory (RAM), read-only memory (ROM), or a non-volatile computer readable storage medium, such as flash memory or a hard disk drive, or any combination thereof. The computer program 141 comprises computer-executable instructions stored or downloaded to the memory 142 and are executable by the processing circuitry 144. Alternatively, the computer program 141 may be transferred to the storage medium 142 using a suitable computer program product, such as a memory stick or in a memory of a device. Thus, the computer program 141 may be stored in any suitable manner in the computer program product. The processing circuity 144 is arranged to cause the AMF device to carry out the steps 910 to 990 of method 900 in accordance with any of the of the described embodiments for steps 910 to 990. The processing circuitry is in one embodiment a general-purpose processor, but may alternatively be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), a complex programmable logic device (CPLD), etc. An I / O interface 143 is provided for communicating with external and / or internal entities using wired communications, e.g., based on Ethernet, and / or wireless communications, e.g., Wi-Fi, and / or a cellular network corresponding to one or a combination of 5G cellular networks, LTE, LTE-advanced, UMTS, or any other current or future wireless network, such as a future 3GPP 6G network, as long as the principles described below are applicable. The AMF device may host a core network function of the communication network, which is configured to communicate with other network functions of the communication network using 3GPP-defined protocols.

[0229] Figure 15 illustrates a block diagram illustrating embodiments of the UDM device 170 in further detail. In practice, the steps 1010 to 1110 of the method 1000 performed by the UDM device are performed by a processing circuitry 174, embodied in one or more microprocessors arranged to execute a computer program 171 that is downloaded to a computer program product 175, here in the form of a suitable computer readable storage medium 172 associated with the microprocessor, such as random access memory (RAM), read-only memory (ROM), or a non-volatile computer readable storage medium, such as flash memory or a hard disk drive, or any combination thereof. The computer program 171 comprises computerexecutable instructions stored or downloaded to the memory 172 and are executable by the processing circuitry 174. Alternatively, the computer program 171 may be transferred to the storage medium 172 using a suitable computer program product, such as a memory stick or in a memory of a device. Thus, the computer program 171 may be stored in any suitable manner in the computer program product. The processing circuity 174 is arranged to cause the UDM device to carry out the steps 1010 to 1110 of method 1000 in accordance with any of the of the described embodiments for steps 1010 to 1110. The processing circuitry is in one embodiment a general-purpose processor, but may alternatively be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), a complex programmable logic device (CPLD), etc. An I / O interface 173 is provided for communicating with external and / or internal entities using wired communications, e.g., based on Ethernet, and / or wireless communications, e.g., WiFi, and / or a cellular network corresponding to one or a combination of 5G cellular networks, LTE, LTE-advanced, UMTS, or any other current or future wireless network, such as a future 3GPP 6G network, as long as the principles described below are applicable. The UDM device may host a core network function of the communication network, which is configured to communicate with other network functions of the communication network using 3GPP-defined protocols.

Claims

CLAIMS:1 . A method performed by a user plane function, UPF, device (120) in a communication network (100), the method comprising: receiving (210) traffic packets from a communication device (105) via a radio access network, RAN, device (110) of the communication network; determining (220) if the traffic packets received from the communication device are comprising at least one anomalous traffic packet; and in response to an anomaly determination that at least one anomalous traffic packet has been received, sending (230) a first message to the RAN device, wherein the first message comprises a first indication for a release of a user data tunnel associated with the communication device.

2. The method according to any claim 1 , wherein the first message is configured to trigger the RAN device to: block traffic packets from the communication device; and / or release user data tunnels associated with the communication device; and / or send a second message to an access and mobility management function, AMF, device (140) in the communication network, wherein the second message comprises the first indication.

3. The method according to claim 1 or 2, wherein a second message is configured to trigger the AMF device to send a request for deregistration of the AMF device to a unified data management, UDM, device (170) in the communication network, wherein the request comprises the first indication.

4. The method according to any of claims 1 to 3 wherein a request is configured to trigger a unified data management, UDM, device (170) in thecommunication network to deny access of the communication device to the communication network.

5. The method according to any of the preceding claims, wherein the first message and / or a second message and / or a request comprises a second indication of an anomaly determination.

6. The method according to any of the preceding claims, wherein the at least one anomalous traffic packet comprises at least one fraudulent traffic packet and / or a set of traffic packets related to a Denial-of-service, DoS, attack.

7. The method according to any of the preceding claims, the method further comprising: receiving (710) an association setup request from a session management function, SMF, device (150) in the communication network; sending (720) a response related to the association setup request to the SMF, device wherein the response comprises a report of at least one user plane function, UPF, device (120) capability.

8. The method according to claim 7, wherein the UPF device capability comprises a feature, wherein the feature comprises at least one of a user data tunnel release feature and an anomaly determination feature.

9. The method according to any of the preceding claims, the method further comprising: receiving (730) a session establishment request from a session management function, SMF, device (150) in the communication network, wherein the session establishment request comprises at least one of an anomaly determination policy and a user data tunnel release policy; and sending a response (740) related to the session establishment request to the SMF.

10. The method according to any of the preceding claims, the method further comprising:receiving (790) a deletion notification from a session management function, SMF, device (150) in the communication network.11 . The method according to any of the preceding claims, the method further comprising: forwarding (750) traffic packets between the RAN device and a network (130).

12. A method performed by a radio access network, RAN, device (110) of a communication network (100), the method comprising: receiving (310) a first message from a user plane function, UPF, device (120) in the communication network, wherein the first message comprises a first indication for a release of a user data tunnel associated with a communication device; and in response to receiving the message: blocking (320) traffic packets from the communication device; and / or releasing (330) user data tunnels associated with the communication device.

13. The method according to claim 12, the method further comprising: sending (850) a second message to an access and mobility management function, AMF, device (140) in the communication network, wherein the second message comprises the first indication.

14. The method according to claim 13 or 12, wherein a second message is configured to trigger an access and mobility management function, AMF, device (140) in the communication network to send a request for deregistration of the AMF device to a unified data management, UDM, device (170), in the communication network, wherein the request comprises the first indication.

15. The method according to claim 14, wherein the request is configured to trigger the UDM device to deny access of the communication device to the communication network.

16. The method according to any of claims 12 to 15, wherein the first message and / or a second message and / or a request comprises a second indication of an anomaly determination.

17. The method according to any of claims 12 to 0, wherein blocking traffic packets associated with the communication device comprises: denying uplink slots for uplink transmission of traffic packets from the communication device.

18. The method according to any of claims 12 to 0, the method further comprising: forwarding (810) traffic packets between the communication device and the UPF.

19. The method according to any of claims 12 to 18, the method further comprising: receiving (860) a third message, from an access and mobility management function, AMF, device (140) in the communication network; forwarding (870) the third message to the communication device; and wherein the third message indicates that all resources of a session associated with the communication device are to be released by the RAN.

20. A method performed by an access and mobility management function, AMF, device (140) in a communication network (100), the method comprising: receiving (410) a second message from a radio access network, RAN, device (110) in the communication network, wherein the second message comprises a first indication for a release of a user data tunnel associated with a communication device;in response to receiving the second message, sending, (420) to a unified data management, UDM, device (170) in the communication network, a request for deregistration of the AMF device, wherein the request comprises the first indication for the release of the user data tunnel associated with the communication device.21 .The method according to claim 20, wherein the second message and / or the request comprises a second indication of an anomaly determination.

22. The method according to any of claims 20 to 21 , wherein the method further comprising: receiving (990), from the UDM device, a response related to the request for deregistration of the AMF.

23. The method according to any of claims 20 to 22, wherein the request is configured to trigger the UDM device to deny access of the communication device to the communication network.

24. The method according to any of claims 20 to 23, the method further comprising: sending (950) via the RAN device to the communication device a third message indicating to release all resources of a session associated with the communication device.

25. The method according to claim 24, wherein the third message is configured to prevent the communication device to send traffic packets to the communication network.

26. The method according to any of claims 20 to 25, the method further comprising: in response to receiving the second message: sending (960) an unsubscribe request associated with a set of subscription data to the UDM device; andreceiving (970) an unsubscribe response associated with the set of subscription data from the UDM device.

27. The method according to any of claims 20 to 26, the method further comprising: receiving (910) a session establishment request from the communication device via the RAN device; in response to receiving the session establishment request, selecting (920) a session management function, SMF, device (150); and sending (930) a session create message to the SMF device.

28. The method according to any of claims 27 , wherein the session create message is configured to trigger the SMF device to select a policy control function, PCF, device (180) in the communication network; send a first request message to retrieve policies for the session associated to the communication device to the PCF device; receive a first response related to the first request message from the PCF device, wherein the response comprises at least one of an anomaly determination policy and a user data tunnel release policy; and select a user plane function, UPF, device (120) supporting the at least one of the anomaly determination policy and the user data tunnel release policy.

29. The method according to claim 28, wherein the request triggers the PCF device to send a second request message to retrieve the policies for the session associated to the communication device to a unified data repository, UDR, device 160; andreceive a second response message comprising the policies for the session associated to the communication device from the UDR, device wherein the response comprises at least one of an anomaly determination policy and a user data tunnel release policy.

30. A method performed by a unified data management, UDM, device (170) in a communication network (100), the method comprising: receiving (510), from an access and mobility management function, AMF, device 140, in the communication network, a request for deregistration of the AMF device, wherein the request comprises a first indication for a release of a user data tunnel associated with a communication device; and in response to receiving the request for deregistration of the AMF device, denying (520) access of the communication device to the communication network.31 . The method according to claim 30, wherein the request comprises a second indication of an anomaly determination.

32. The method according to any of claims 30 to 31 , wherein denying the communication device access to the communication network comprises: sending an update message to a unified data repository, UDR, device (160) in the communication network.

33. The method according to claim 0, wherein denying the communication device access to the communication network comprises: receiving a response to the update message from, UDR, device (160) in the communication network.

34. The method according to claim 0, wherein the update message is configured to trigger the UDR device to modify subscription data associated with the communication device.

35. The method according to claim 0, wherein modifying the subscription data associated to the communication device comprises changing the subscription data associated to the communication device to denied.

36. The method according to any of claims 30 to 0, the method further comprising: setting (1080) a communication device purged flag associated with an access type; and sending (1090) to the AMF device a response related to the request of deregistration of the AMF.

37. The method according to any of claims 30 to 36, the method further comprising: receiving (1010) an unsubscribe request associated with the set of subscription data from the AMF; in response to receiving the unsubscribe request of the AMF device, unsubscribing (1020) the AMF device from at least a part of the set of subscription data; and sending (1050), to the AMF device, an unsubscribe response associated with the set of subscription data.

38. The method according to any of claims 30 to 37, the method comprising: sending (1030), to a unified data repository, UDR, device (160) in the communication network, an unsubscribe request associated with set of subscription data; and receiving (1040), from the UDR device, an unsubscribe response associated with the set of subscription data.

39. The method according to any of claims 30 to 38, the method further comprising:sending (1100) a session release request to a session management function, SMF, device (150); and receiving (1110) a session release response from the SMF device.

40. A user plane function, UPF, device (120) in a communication network (100), configured to: receive traffic packets from a communication device via a radio access network, RAN, device (110) of the communication network; determine if the traffic packets received from the communication device are comprising at least one anomalous traffic packet; and in response to an anomaly determination that at least one anomalous traffic packet has been received, send a first message to the RAN device, wherein the first message comprises a first indication for a release of a user data tunnel associated with the communication device.

41. The UPF device according to claim 40, configured to perform the method according to any of claims 2 to 10.

42. A user plane function, UPF, device (120) in a communication network (100), comprising a processor and a memory, the memory containing instructions executable by the processor whereby the UPF device is configured to: receive traffic packets from a communication device via a radio access network, RAN, device (110) of the communication network; determine if the traffic packets received from the communication device are comprising at least one anomalous traffic packet; and in response to an anomaly determination that at least one anomalous traffic packet has been received, send a first message to the RAN device, wherein the first message comprises a first indication for a release of a user data tunnel associated with the communication device.

43. The UPF device according to claim 42, configured to perform the method according to any of claims 2 to claim 10.

44. A radio access network, RAN, device (110) in a communication network (100), configured to: receive a first message from a user plane function, UPF, device (120) in the communication network, wherein the message comprises a first indication for a release of a user data tunnel associated with a communication device; in response to receiving the message: block traffic packets from the communication device; and / or release user data tunnels associated with the communication device and the RAN device.

45. The RAN device according to claim 44, configured to perform the method according to any of claims 13 to 19.

46. A radio access network, RAN, device (110) in a communication network (100), comprising a processor and a memory, the memory containing instructions executable by the processor whereby the RAN device is configured to: receive a first message from a user plane function, UPF, device (120) in the communication network, wherein the message comprises a first indication for a release of a user data tunnel associated with a communication device; in response to receiving the message: block traffic packets from the communication device; and / or release user data tunnels associated with the communication device and the RAN.

47. The RAN device according to claim 46, configured to perform the method according to any of claims 13 to 19.

48. An access and mobility management function, AMF, device (140) in a communication network (100), configured to: receive a second message from a radio access network, RAN, device (110) in the communication network, wherein the message comprises a first indication for a release of a user data tunnel associated with a communication device; in response to receiving the second message, send, to a unified data management, UDM, device in the communication network, a request for deregistration of the AMF device, wherein the request comprises the first indication for the release of the user data tunnel associated with the communication device.

49. The AMF device according to claim 48, configured to perform the method according to any of claims 21 to 29.

50. An access and mobility management function, AMF, device (140) in a communication network (100), comprising a processor and a memory, the memory containing instructions executable by the processor whereby the AMF device is configured to: receive a second message from a radio access network, RAN, device (110) in the communication network, wherein the message comprises a first indication for a release of a user data tunnel associated with a communication device; in response to receiving the second message, send, to a unified data management, UDM, device in the communication network, a request for deregistration of the AMF device, wherein the request comprises the first indication for the release of the user data tunnel associated with the communication device.51 .The AMF device according to claim 50, configured to perform the method according to any of claims 21 to 29.

52. A unified data management, UDM, (170) device in a communication network (100), configured to: receive, from an access and mobility management function, AMF, device (140) in the communication network, a request for deregistration of the AMF device, wherein the request comprises a first indication for a release of a user data tunnel associated with a communication device; and in response to receiving the request for deregistration of the AMF device, deny access of the communication device to the communication network.

53. The UDM device according to claim 52, configured to perform the method of any of claims 31 to 39.

54. A unified data management, UDM, device, (170) in a communication network (100), comprising a processor and a memory, the memory containing instructions executable by the processor whereby the UDM device is configured to: receive, from an access and mobility management function, AMF, device in the communication network, a request for deregistration of the AMF device, wherein the request comprises a first indication for a release of a user data tunnel associated with a communication device; and in response to receiving the request for deregistration of the AMF device, deny access of the communication device to the communication network.

55. The UDM device according to claim 54, wherein the UDM device is configured to perform the method according to any of claims 31 to 39.

56. A non-transitory computer readable medium (122, 112, 142, 172) which comprises instructions that, when executed on: at least one processor (124) of a user plane function, UPF, device(120) cause the at least one processor of the UP F device to carry out the method according to any one of claims 1 to 10; and / or at least one processor (114) of a radio access network, RAN device (110), cause the at least one processor of the RAN device to carry out the method according to any one of claims 12 to 19; and / or at least one processor (144) of an access and mobility management function, AMF, device (140) cause the at least one processor of the AMF device to carry out the method according to any one of claims 20 to 29; and / or at least one processor (174) of a unified data management, UDM device (170), cause the at least one processor of the UDM device to carry out the method according to any one of claims 30 to 39.

57. A computer program (121 , 111 , 141 , 171 ) comprising instructions which, when executed on: at least one processor (124) of a user plane function, UPF, device (120) cause the at least one processor of the UPF device to carry out the method according to any one of claims 1 to 10; and / or at least one processor (114) of a radio access network, RAN, device (110) cause the at least one processor of the RAN device to carry out the method according to any one of claims 12 to 19; and / or at least one processor (144) of an access and mobility management function, AMF, device (140) cause the at least one processor of the AMF device to carry out the method according to any one of claims 20 to 29; and / or at least one processor (174) of a unified data management, UDM, device (170) cause the at least one processor of the UDM device to carry out the method according to any one of claims 30 to 39.

Citation Information

Patent Citations

  • Device monitoring, and deregistration method and apparatus

    EP3687135A1

  • Method and system for user plane traffic characteristics and network security

    US20190068625A1